Privacy Policy

Last updated: 2026-09-22

1. Who we are

OpenDQV Cloud is operated by BGMS Consultants Limited, trading as OpenDQV Cloud, a company registered in England and Wales (company number 10802377). Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We provide write-time data quality enforcement services for enterprise customers.

For questions about this policy: privacy@opendqv.com

2. What data we collect and why

2.1 Account and signup data

When you create a trial account we collect: your name, email address, and company name. We use this to create your account, send you the trial token, and contact you about your trial. Legal basis: contract performance (Article 6(1)(b) GDPR).

After signup we ask for a short profile: first name, last name, company name, company website, role, country, industry, team size, phone number, LinkedIn URL, and what you are trying to fix. The profile is stored by our control plane in Cloudflare D1, our control-plane database, regardless of the region you chose for your engine. That database is currently served from Cloudflare's Western Europe region; Cloudflare does not offer a storage-region setting for it, so we cannot commit to that location contractually. The profile is used for onboarding, customer success and lawful business-to-business communication; your industry, team size, country and plan are also copied into the aggregate statistics described in section 2.6. Legal basis: legitimate interests (Article 6(1)(f) GDPR); you may object at any time (section 5). It is deleted with your account (section 3).

Each signup attempt is logged (email address and its domain, IP address, outcome) for abuse prevention and deleted after 30 days.

2.2 Validation audit events

When you use the API to validate data, we store metadata about each validation: contract name, whether the record was valid, error counts, rule failure names, latency, timestamp, the calling API token's identity, and any correlation id (record id) or client and agent name your integration sends with the request. We do not store the actual data records you validate — validation payloads are held in memory only for as long as they are being validated. They are not written to the audit trail, to backups, to application logs, to the engine's durable audit queue, or to metrics; only the decision is recorded (pass, would-block or blocked, with rule names, hashes, and any correlation id or caller identity you send with the request).

Audit events are stored, and validation is processed, in the cloud region you selected at signup. The available regions are shown in the region selector when you sign up, and we add regions over time. Where your validations take place is your decision: you would typically choose a region in your own country or jurisdiction, but the choice is always yours. Your audit events are never stored in, or replicated to, any region other than the one you selected. The only usage figures that leave that region are the daily counts described in section 2.6, which are held in our control plane. Audit events are processed on your behalf: for any personal data they contain, you are the controller and we act as your processor under §6 — we do not determine the purposes of that data.

2.3 Usage and billing data

We count ODUs — the engine-uptime billing unit defined in our Terms of Service — consumed per account. These are aggregate counts only — no validation content is included. ODU totals are processed by our coordinator (Cloudflare Workers) and used for billing and for operating the Service (capacity, abuse prevention, billing reconciliation and onboarding). Legal basis: contract performance for billing (Article 6(1)(b) GDPR); legitimate interests for operating the Service (Article 6(1)(f) GDPR) — you may object at any time (section 5).

Payment information is handled entirely by Stripe. We never store card details. We receive a Stripe customer ID and subscription ID to manage your billing relationship.

2.4 Technical logs

We retain application logs (request method, path, status code, latency, IP address) for 30 days for security and debugging purposes. Legal basis: legitimate interests (Article 6(1)(f) GDPR).

Our control plane's operational logs are Cloudflare Workers Logs, retained for 7 days; some business-event lines include your account email address. Cloudflare does not offer a storage-region setting for Workers Logs; they are processed under Cloudflare's data processing terms (section 4).

2.5 Feedback you send us

Feedback sent from the dashboard (your email address, the category you chose, the message and the page you were on) is stored with your account and deleted with it.

2.6 Industry data-quality findings

We publish periodic industry findings, such as our annual Data Quality Report, from counts derived from your usage: your sector, your pass rates in banded ranges, and how many checks ran by rule family. They never contain the records you validate, record identifiers, rule or contract names, or anything that names your company, your workspace or any person. Every published figure rests on at least ten workspaces (twenty for anything ranked), on every breakdown; the current methodology is published at /methodology. Legal basis: legitimate interests (Article 6(1)(f) GDPR) — benchmarking data quality and producing industry research.

You may exclude your workspace at any time, free of charge, using the report setting in your workspace profile; that setting binds us for every edition whose cut-off falls while your account is open. A named contact may also object to the use of data relating to them by emailing privacy@opendqv.com; an objection is honoured without asking for reasons and removes the workspace from every cross-customer output. Both take effect for every edition whose published cut-off has not passed; reports already issued cannot be withdrawn.

These counts are the only usage figures that leave the region you selected for your engine; they are held in our control plane (section 2.1). Per-workspace counts are kept while your account exists plus the deletion window in section 3, then reduced to sector totals that carry no workspace identifier, which we keep indefinitely — or discarded, if your workspace was excluded when it closed. Methodology, thresholds and cadence may change between editions; the floor of ten only ever tightens, and each edition's methodology page stays published.

3. Data retention

Audit events are retained according to your plan's audit retention window — 30 days on Trial and Standard plans and 365 days on Enterprise (the retention windows are stated in our Terms of Service, section 5, whose notice protections apply to any change). Older events are removed on a rolling basis; the sealed audit chain keeps a tamper-evident attestation of removed events so the integrity of your audit trail remains verifiable. You may export your full audit log at any time via the dashboard or the API (GET /api/v1/audit/export) and request deletion (see §5).

Account data is retained while you have an account and is permanently deleted after account closure — 30 days after a paid account closes, 7 days after a trial ends (see our Terms of Service) — unless you request earlier deletion. Records we are legally required to keep, such as invoicing and tax records, are retained only as long as the law requires. When your account is deleted, the daily counts in section 2.6 are reduced to sector totals that carry no workspace identifier (or discarded, if your workspace was excluded); those totals are not personal data and are kept indefinitely.

Application logs: 30 days.

4. Who we share data with

  • Cloudflare — web app hosting, request routing and coordinator (global edge network; stores your account data — name, email, company and the onboarding profile in section 2.1 — plus aggregate usage counts, the signup-attempt log and the operational logs in section 2.4, never validation content — processing under Cloudflare's data processing terms)
  • AWS / Microsoft Azure / Google Cloud — VCE infrastructure (your validation is processed, and your audit trail stored, in the region you selected; your contract definitions (the YAML you author) are stored on Amazon S3 in the jurisdiction you selected, whichever cloud runs your engine)
  • Stripe — payment processing
  • Resend — transactional email delivery (sign-in links, account, billing and lifecycle notices; processes your name and email address, never validation content)

We do not sell your data. We do not share it with third parties for marketing. All processors are bound by GDPR-compliant data processing agreements. The canonical sub-processor list, with a dated change log, is maintained at /subprocessors; the list above mirrors it.

5. Your rights

Under UK GDPR, EU GDPR, and equivalent provisions of other data protection laws — whichever apply to you — you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data (“right to be forgotten”)
  • Portability — receive your data in a machine-readable format
  • Restriction — request we limit processing of your data while an objection or accuracy dispute is resolved
  • Objection — object to processing based on legitimate interests

These rights apply in the circumstances set out in the applicable law. To exercise any right: email privacy@opendqv.com. To exclude your workspace from our published findings, use the report setting in your workspace profile (section 2.6). We respond within one month (extendable by up to two further months for complex requests — we will tell you if we need longer). If you wish to complain about how we have handled your personal data, email the same address; we acknowledge complaints within 30 days and tell you the outcome. If your personal data was submitted to the Service by one of our customers — for example, in records they validate — we will refer your request to that customer, who is the controller for it. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), our UK supervisory authority, or with the data protection authority in your own country.

6. Business customers — data processing

If you use OpenDQV Cloud to validate personal data on behalf of your customers or employees, you are the data controller and we are a data processor under Article 28 GDPR. Our Data Processing Agreement applies and is published for review.

Reminder: validation payloads are held in memory only while they are validated and are not written to the audit trail, backups, application logs, the engine's durable audit queue, or metrics. The DPA governs the processing of any personal data present in validation requests, which occurs transiently in memory.

7. International transfers

Your validation is processed, and your audit trail stored, in the region you selected at signup; your contract definitions (the YAML you author) are stored on Amazon S3 in the jurisdiction you selected, whichever cloud runs your engine. Validation payloads are held in memory only while they are validated and are not written to the audit trail, backups, application logs, the engine's durable audit queue, or metrics, in any region; the audit trail is never stored in any other region. The choice of region is yours, from the regions offered at signup, and it is fixed for the life of your account. You would typically choose a region in your own country or jurisdiction; you may choose any region we offer.

Requests to the Service travel over Cloudflare's global edge network before reaching your selected region; Cloudflare acts as a processor under its data processing addendum, incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, and stores no validation content. If you choose a region outside your own country or legal jurisdiction, that choice is your instruction to process and store your audit metadata in that region. Where UK or EU GDPR applies to you and the region you choose sits outside the UK and the European Economic Area, that choice is an international transfer under GDPR Chapter V; our Data Processing Agreement describes the applicable safeguards. Equivalent transfer rules under other data protection laws may apply if you are subject to them and choose a region outside their recognised zone.

8. Security

We protect your data with appropriate technical and organisational measures: all traffic is encrypted in transit (TLS), data is encrypted at rest on every cloud provider we run on, access to production systems is restricted and authenticated, and your audit trail is protected by a sealed, tamper-evident hash chain that makes alteration or deletion detectable. If we become aware of a personal data breach affecting your data, we will notify you without undue delay.

9. Cookies

The web app uses a secure, HttpOnly session cookie to authenticate your session. This cookie is set by the coordinator and contains only a random session identifier. As a strictly necessary cookie it requires no consent. It is encrypted in transit (HTTPS only) and cannot be read by JavaScript.

We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

10. Changes to this policy

We will notify you by email before making material changes to this policy. The “last updated” date at the top of this page records the most recent revision.

OpenDQV Cloud — Terms of Service · Data Processing Agreement